cbcvebase.
CVE-2015-2019
published 2015-06-28

CVE-2015-2019: IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix…

PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.43%
34.9th percentile
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not prevent caching of documents retrieved in SSL sessions, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation.

Affected

8 ranges
VendorProductVersion rangeFixed in
ibmtivoli_directory_server
ibmtivoli_directory_server
ibmtivoli_directory_server
ibmtivoli_directory_server
ibmtivoli_directory_server
ibmtivoli_directory_server
msrcskype_for_business_server_2015_cu13
msrcskype_for_business_server_2019_cu7

CVSS provenance

nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv6.8MEDIUM
vendor_msrc7.2HIGH
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.